Intelligent Network False Information Recognition and Early Warning System Based on Multimodal Behavior Atlas

Through the construction of a multimodal behavior map system and a timing reasoning model, the problem of insufficient data modeling in the existing technology is solved, efficient identification and real-time early warning of fraudulent behavior is achieved, and identification accuracy and early warning timeliness are improved.

CN120145279BActive Publication Date: 2025-07-18HENAN SONGSHAN LAB IND RES INST CO LTD LUOYANG BRANCH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510615893.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-18
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

The existing technology lacks the unified modeling ability of cross-platform and cross-modal data in the anti-fraud system, and it is difficult to capture the dynamic evolutionary timing characteristics of fraudulent behavior, resulting in low recognition rate of gang crimes, high false alarm rate, and poor real-time performance.

Method used

An intelligent network false information identification system based on multimodal behavior map is adopted. Through the dynamic behavior map construction module, timing inference model training module and risk warning module, a dynamic behavior map is built, a false information timing inference model is trained, and a risk score and warning are carried out. Combined with the graph database and large language model, real-time analysis and recognition of cross-platform data is realized.

Benefits of technology

It significantly improves the accuracy of identification of fraud gangs, enhances correlation analysis capabilities, reduces the risk of misjudgment, adapts to complex scenarios, and can identify hidden relationships between users, devices, and accounts in real time, reduces false alarms, and improves the timeliness of early warnings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145279B_ABST
    Figure CN120145279B_ABST
Patent Text Reader

Abstract

The present application discloses an intelligent network false information identification and early warning system based on a multi-modal behavior graph, specifically relating to the field of intelligent network false information identification and early warning. A specific implementation manner of the system includes: a dynamic behavior graph construction module configured to construct a dynamic behavior graph, and to monitor in real time new behavior stream data corresponding to original user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data; a time series inference model training module configured to construct a behavior sequence data set with timestamps and to train an initial false information time series inference model; and a risk early warning module configured to identify false information in the updated dynamic behavior graph according to the false information time series inference model and a historical abnormal behavior graph library, so as to generate corresponding false identification information. This implementation manner captures dynamic behavior features through a time series inference model, distinguishes normal operations from fraudulent behaviors, and reduces false alarms caused by static rules.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of intelligent network false information identification and early warning, and specifically to an intelligent network false information identification and early warning system based on a multi-modal behavior graph. Background Art

[0002] Existing anti-fraud technologies mainly rely on single-modal data analysis and lack the ability to unify the modeling of cross-platform and cross-modal data. Traditional systems match through preset static rules or a single machine learning model, making it difficult to capture the dynamic evolution time series characteristics of fraud behaviors. Although some solutions use large language models to analyze text semantics, they are not deeply integrated with the behavior graph, resulting in the disconnection between semantic risks and entity associations. In addition, existing technologies cannot effectively associate cross-platform entities, and the data island problem leads to a low recognition rate and a high false alarm rate for gang crimes, and relies on manual review after the event, with poor real-time performance. Although large model solutions can analyze text intentions, they face problems such as high computing power requirements and difficulty in real-time deployment. Existing fusion systems also lack a feature collaboration mechanism guided by the graph topology, which restricts the timeliness of early warning. Summary of the Invention

[0003] This section of the content of the present application is used to briefly introduce concepts, which will be described in detail in the subsequent detailed implementation section. This section of the content of the present application is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0004] Some embodiments of the present application propose an intelligent network false information identification and early warning system based on a multi-modal behavior graph to solve the technical problems mentioned in the above background art section.

[0005] In a first aspect, some embodiments of the present application provide an intelligent network false information recognition and early warning system based on a multi-modal behavior graph. The intelligent network false information recognition and early warning system includes: a data collection module configured to collect raw user behavior data from multiple data sources, where the raw user behavior data includes: multiple entity names; a dynamic behavior graph construction module configured to construct a dynamic behavior graph according to the raw user behavior data, and to monitor in real time new behavior stream data corresponding to the raw user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph; a time series reasoning model training module configured to extract positive and negative samples from a historical false case library, construct a behavior sequence data set with timestamps, and train an initial false information time series reasoning model according to the behavior sequence data set to obtain a trained false information time series reasoning model, where the false information time series reasoning model is used to identify the risk score of the dynamic behavior graph; a risk early warning module configured to identify false information in the updated dynamic behavior graph according to the false information time series reasoning model and a historical abnormal behavior graph library to generate corresponding false identification information and perform risk early warning, where the false identification information includes: a risk identification result and an associated evidence chain.

[0006] Optionally, constructing a dynamic behavior graph according to the raw user behavior data includes: extracting each entity node and the association relationship between entities from the raw user behavior data; generating a dynamic behavior graph corresponding to each entity node and the association relationship between entities based on a graph database, where the node attributes of the entity nodes in the dynamic behavior graph include: timestamp, operation type, edge weight.

[0007] Optionally, monitoring in real time new behavior stream data corresponding to the raw user behavior data and updating the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph includes: monitoring new behavior stream data corresponding to the raw user behavior data in multiple data sources within a preset time period; in response to the monitored new behavior stream data indicating a new device binding an account, parsing the new behavior stream data into a new edge; in response to the monitored new behavior stream data indicating a cross-region login behavior, parsing the new behavior stream data into an updated edge attribute; updating the dynamic behavior graph according to the new edge and the updated edge attribute; adjusting the weight of the historical edges of the dynamic behavior graph according to a preset rule; in response to determining that a device corresponding to a device entity node in the dynamic behavior graph meets a preset risk condition, expanding two-hop neighbors outward with the device entity node as the center to construct a subgraph, and recalculating the weights of all edges of the dynamic behavior graph.

[0008] Optionally, training the initial false information temporal reasoning model according to the behavior sequence data set to obtain a trained false information temporal reasoning model includes: fusing the social text features and transaction data features included in each behavior sequence data in the behavior sequence data set to generate fused features, obtaining a fused feature set; training the initial false information temporal reasoning model according to the fused feature set to obtain a trained false information temporal reasoning model.

[0009] Optionally, identifying false information in the updated dynamic behavior graph according to the false information temporal reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information includes: inputting the updated dynamic behavior graph into the false information temporal reasoning model to obtain a behavior risk score corresponding to the updated dynamic behavior graph as a risk identification result; determining the similarity between the updated dynamic behavior graph and each historical abnormal behavior graph in the historical abnormal behavior graph library to obtain a similarity set; determining the historical abnormal behavior graph corresponding to the similarity that meets the preset conditions in the similarity set as an associated historical abnormal behavior graph, obtaining a group of associated historical abnormal behavior graphs; in response to determining that the behavior risk score is greater than or equal to the preset score, performing multi-dimensional verification on the updated dynamic behavior graph and outputting multi-dimensional association information; merging the group of associated historical abnormal behavior graphs and the multi-dimensional association information into an associated evidence chain; merging the risk identification result and the associated evidence chain into false identification information.

[0010] In a second aspect, some embodiments of the present application provide an intelligent network false information identification and early warning device based on a multi-modal behavior graph. The device includes: a collection unit configured to collect original user behavior data from multiple data sources, where the original user behavior data includes: a plurality of entity names; a graph construction unit configured to construct a dynamic behavior graph according to the original user behavior data, and to monitor in real time new behavior stream data corresponding to the original user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph; a model training unit configured to extract positive and negative samples from a historical false case library, construct a behavior sequence data set with time stamps, and train an initial false information temporal reasoning model according to the behavior sequence data set to obtain a trained false information temporal reasoning model, where the false information temporal reasoning model is used to identify the risk score of the dynamic behavior graph; a risk early warning unit configured to identify false information in the updated dynamic behavior graph according to the false information temporal reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information and perform risk early warning, where the false identification information includes: a risk identification result and an associated evidence chain.

[0011] In a third aspect, some embodiments of the present application provide an electronic device, including: one or more processors; a storage device storing one or more programs thereon, and when the one or more programs are executed by the one or more processors, the one or more processors implement the system described in any implementation manner of the first aspect above.

[0012] In a fourth aspect, some embodiments of the present application provide a computer-readable medium storing a computer program thereon, where when the program is executed by a processor, the system described in any implementation manner of the first aspect above is implemented.

[0013] The above various embodiments of the present application have the following beneficial effects: Through the intelligent network false information identification and warning system based on the multi-modal behavior graph in some embodiments of the present application, through the synergistic effect of the dynamic behavior graph and the large language model, the identification accuracy of fraud gangs is significantly improved, specifically manifested as follows: 1. Enhance the correlation analysis ability: Utilize the topological structure of the graph to fuse multi-modal data, break through the limitations of traditional single-dimensional detection, and effectively identify the hidden correlation relationships among users, devices, and accounts; 2. Reduce the risk of misjudgment: Capture dynamic behavior characteristics (such as abnormal transfer frequency, device switching rules) through the time series reasoning model, distinguish normal operations from fraudulent behaviors, and reduce false alarms caused by static rules; 3. Adapt to complex scenarios: Have stronger robustness to the phased evolution of gang behaviors (such as decentralized registration, centralized crime), avoid the situation in the prior art where traditional models are difficult to identify phased split behaviors due to the inability to capture long-term cross-platform behaviors, resulting in missed detections. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the embodiments of the present application will become more apparent. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.

[0015] Figure 1 is a flowchart according to some embodiments of the intelligent network false information identification and warning system based on the multi-modal behavior graph of the present application;

[0016] Figure 2 is an exemplary architecture diagram of the intelligent network false information identification and warning system based on the multi-modal behavior graph of some embodiments of the present application;

[0017] Figure 3 is a schematic structural diagram according to some embodiments of the intelligent network false information identification and warning device based on the multi-modal behavior graph of the present application;

[0018] Figure 4It is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present application;

[0019] Explanation of reference numerals in the drawings: 301 - acquisition unit; 302 - atlas construction unit; 303 - model training unit; 304 - risk warning unit. Detailed implementation manners

[0020] Embodiments of the present application will be described in more detail below with reference to the drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not used to limit the protection scope of the present application.

[0021] In addition, it should be noted that, for the sake of convenience of description, only parts related to the invention are shown in the drawings. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0022] It should be noted that the concepts such as "first" and "second" mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence relationship of the functions performed by these devices, modules or units.

[0023] It should be noted that the modifications of "one" and "multiple" mentioned in the present application are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0024] The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0025] The present application will be described in detail below with reference to the drawings and in combination with embodiments.

[0026] Figure 1 It is a process of some embodiments of an intelligent network false information identification and warning system based on a multi-modal behavior atlas in some embodiments of the present application. The intelligent network false information identification and warning system based on the multi-modal behavior atlas includes the following steps:

[0027] Step 101, a data acquisition module, is configured to: acquire original user behavior data from multiple data sources.

[0028] In some embodiments, the data acquisition module is configured to: collect raw user behavior data from multiple data sources. Among them, the above-mentioned raw user behavior data includes: multiple entity names. The data acquisition module can be a processor for collecting data in the intelligent network false information identification and early warning system. For example, the data acquisition module can collect structured and unstructured data in real time from communication operators, payment platforms, and social networks, use large language models to perform intent recognition and semantic annotation on unstructured text, and solve the problem of cross-platform data heterogeneity through entity alignment technology. The raw user behavior data can include login logs, transaction records, device fingerprint databases, etc. of multiple users. The raw user behavior data can represent the account transaction behavior data of one or more users. For example, the raw user behavior data can represent the behavior data of users transferring funds to each other through devices. The multiple data sources can refer to data sources such as communication operators, payment platforms, and social network platforms.

[0029] It should be noted that, please refer to Figure 2 , the intelligent network false information identification and early warning system can be composed of a data acquisition module (multi-modal data acquisition layer), a dynamic behavior graph construction module (dynamic behavior graph construction layer), a time series reasoning model training module (time series reasoning engine / reasoning layer), and a risk early warning module (early warning decision module / application layer). The time series reasoning model training module can be a processor for training the false information time series reasoning model. The dynamic behavior graph construction module can be a processor for constructing a dynamic behavior graph.

[0030] The multi-modal data acquisition layer collects structured and unstructured data in real time from communication operators, payment platforms, and social networks, uses large language models to perform intent recognition and semantic annotation on unstructured text, and solves the problem of cross-platform data heterogeneity through entity alignment technology.

[0031] The dynamic behavior graph construction layer, based on knowledge graph technology, uses entities such as user ID, device number, and account (bank account) as nodes, and uses interaction relationships (such as call frequency , transfer path ) as edges to construct a multi-modal dynamic behavior graph. Among them, the entity nodes are embedded by fusing traditional features and semantic vectors extracted by large models, and the edge weights are updated in real time through the following formula:

[0032]

[0033] Among them, is the time decay factor (default value is 0.05), and It is the time-triggered increment, which refers to the enhancement factor added to the edge weight when the abnormal behavior threshold under certain time dimensions is met. For example, "transferring more than 5 times a day" triggers an increase in the edge weight by 0.3. This value is a preset hyperparameter and can be configured and tuned according to actual business requirements or historical data statistics. It is the timestamp of the last update of the edge. t represents the current time.

[0034] : It represents the updated weight of the edge between node i and node j at the current moment t, reflecting the latest behavioral association strength between the two entities.

[0035] : It represents the weight of the edge between node i and node j at the time of the last update ;

[0036] λ: It is the time decay factor, which controls the decay rate of the association over time. The default value is 0.05 and it is adjustable. This factor is used to weaken the impact of outdated behaviors on the current judgment.

[0037] : It represents the time interval from the last behavior occurrence to the current time, and the unit can be hours or seconds, depending on the system setting.

[0038] : It is the time-triggered increment, which is the increment of the weight when specific high-frequency behavior conditions are met. For example, when "transferring more than 5 times a day" is triggered, the increment is set to 0.3. This value is a preset hyperparameter and can be optimized according to business rules or historical statistics.

[0039] : It is the Indicator Function. If the set event condition is met, the value is 1; otherwise, it is 0. It is used to indicate whether to perform the adjustment of the edge weight increment.

[0040] The time series inference engine (inference layer) adopts a fusion model of graph neural network (GNN) and Transformer. Among them, the GNN layer is used to capture the topological association between entities (such as the account sharing relationship of fraud gangs), and the Transformer layer is used to analyze the time series evolution pattern of fraud behaviors (such as the behavior chain from the induction period to the transfer period), and finally outputs the real-time risk score of user behaviors.

[0041] The risk warning module (application layer) is based on the multi-level risk score fusion algorithm to achieve the full-chain prevention and control from individual anomaly detection to the case stringing and analysis of gang crimes. The risk warning module can be a processor with a multi-level risk score fusion algorithm built in.

[0042] Step 102: The dynamic behavior graph construction module is configured to: construct a dynamic behavior graph based on the above-mentioned original user behavior data, and real-time monitor the new behavior stream data corresponding to the above-mentioned original user behavior data, and update the topological structure of the above-mentioned dynamic behavior graph according to the above-mentioned new behavior stream data to obtain an updated dynamic behavior graph.

[0043] In some embodiments, the dynamic behavior graph construction module is configured to: construct a dynamic behavior graph based on the above-mentioned original user behavior data, and real-time monitor the new behavior stream data corresponding to the above-mentioned original user behavior data, and update the topological structure of the above-mentioned dynamic behavior graph according to the above-mentioned new behavior stream data to obtain an updated dynamic behavior graph. Extract various entity nodes (including user ID, device number, bank account) and association relationships (such as IP address sharing, transfer frequency, call frequency, transfer path) from the above-mentioned original user behavior data. Among them, the user ID can represent the ID name of the transfer user or the receiving user. The device number can represent the ID number of the device operated by the transfer user or the receiving user. The bank account can represent the bank account of the transfer user or the receiving user. IP address sharing can mean that two users share an IP address. The transfer frequency can represent the number of transfers of a certain bank account within a preset time period. The call frequency can represent the frequency of calls between two devices. The transfer path can represent the way of transfer. For example, it can be by transferring from a social platform to a bank account, or by transferring from a bank account to a bank account.

[0044] In practice, the dynamic behavior graph construction module can construct a dynamic behavior graph based on the above-mentioned original user behavior data through the following steps:

[0045] First step, extract various entity nodes and the association relationships between the entities from the above-mentioned original user behavior data. Here, various entity nodes (including user ID, device number, bank account) and association relationships (such as IP address sharing, transfer frequency, call frequency, transfer path) can be extracted from the above-mentioned original user behavior data by means of traversal.

[0046] Step 2: Based on the graph database, generate a dynamic behavior graph corresponding to each of the above entity nodes and the association relationships between entities. Among them, the node attributes of the entity nodes in the above dynamic behavior graph include: timestamp, operation type, and edge weight. The graph database may refer to the Neo4j graph database. For example, entities such as user ID, device number, and bank account can be used as nodes, and association relationships (such as IP address sharing, transfer frequency, call frequency, transfer path) can be used as edges to construct a dynamic behavior graph. The operation type can represent the type of behavior. For example, the operation type can represent a browsing operation type or a transfer operation type. The timestamp can represent the time node when the behavior occurs. The generation method of the edge weight can refer to the above generation method of the edge weight.

[0047] In practice, the dynamic behavior graph construction module can update the topological structure of the above dynamic behavior graph through the following steps to obtain an updated dynamic behavior graph:

[0048] Step 1: Listen for new behavior stream data corresponding to the above original user behavior data in multiple data sources within a preset time period. The preset time period may refer to the preset duration closest to the current time. For example, listen for whether there is new behavior stream data such as new user login / transfer or device binding.

[0049] Step 2: In response to the new behavior stream data indicating a new device binding an account, parse the new behavior stream data into a new edge. For example, if it is detected that the new behavior stream data indicates a new device binding an account, it is parsed as: "new edge (device, account, binding relationship)".

[0050] Step 3: In response to the new behavior stream data indicating a cross-region login behavior, parse the new behavior stream data into an updated edge attribute. For example, if the new behavior stream data indicates a cross-region login behavior, then generate "updated edge attribute (login location, time)".

[0051] Step 4: Update the above dynamic behavior graph according to the above new edge and the above updated edge attribute. For example, a new edge can be added to the dynamic behavior graph, or the corresponding edge attribute (updated edge attribute) can be updated on the dynamic behavior graph.

[0052] Step 5: Adjust the weights of the historical edges of the above dynamic behavior graph according to preset rules.

[0053] For example, adjust the weights of the historical edges in the above dynamic behavior graph according to preset rules (such as the time decay factor). The weight adjustment of the historical edges adopts an exponential decay strategy, that is:

[0054]

[0055] Among them, is the time decay factor (default value is 0.05), and it is is the time trigger increment, which refers to the enhancement factor added to the edge weight when the abnormal behavior threshold under certain time dimensions is met. For example, "transfer more than 5 times a day" triggers an increase in the edge weight by 0.3. This value is a preset hyperparameter and can be configured and optimized according to actual business requirements or historical data statistics. is the timestamp of the last update of the edge. t represents the current time.

[0056] : represents the updated weight of the edge between node i and node j at the current moment t, reflecting the latest behavior association strength between the two entities.

[0057] : represents the weight of the edge between node i and node j at the time of the last update ;

[0058] λ: the time decay factor, which controls the decay rate of the association over time. The default value is 0.05 and it is adjustable. This factor is used to weaken the influence of outdated behaviors on the current judgment.

[0059] : represents the time interval from the last behavior occurrence to the current, and the unit can be hours or seconds, depending on the system setting.

[0060] : the time trigger increment, which is the enhancement amount of the weight when specific high-frequency behavior conditions are met. For example, when "transfer more than 5 times a day" is triggered, the increment is set to 0.3. This value is a preset hyperparameter and can be optimized according to business rules or historical statistics.

[0061] : the event indicator function (Indicator Function), which takes the value of 1 if the set event condition is met, otherwise 0. It is used to indicate whether to perform the adjustment of the edge weight increment.

[0062] Step 6: In response to determining that a device corresponding to a device entity node in the dynamic behavior graph meets the preset risk condition, taking this device entity node as the center, expand two-hop neighbors outward to construct a subgraph, and recalculate the weights of all edges in the dynamic behavior graph. The preset risk condition can be: the number of bound accounts of the same device within 24 hours > 5. If new or stronger abnormal interaction patterns are found among multiple nodes, use it as a local subgraph to replace the original structure in the dynamic behavior graph.

[0063] Step 103, the temporal reasoning model training module, is configured to: extract positive and negative samples from the historical false case database, construct a timestamped behavior sequence dataset, and train an initial false information temporal reasoning model according to the above behavior sequence dataset to obtain a trained false information temporal reasoning model.

[0064] In some embodiments, the temporal reasoning model training module is configured to: extract positive and negative samples from the historical false case database, construct a timestamped behavior sequence dataset, and train an initial false information temporal reasoning model according to the above behavior sequence dataset to obtain a trained false information temporal reasoning model. Among them, the false information temporal reasoning model is used to identify the risk score of the dynamic behavior graph. False information can represent fraud information, that is, whether the user has been defrauded. The historical false case database can refer to the historical fraud case database. For example, historical fraud cases can represent cases of being defrauded by telecommunications fraud. The behavior sequence data can represent the behavior data of whether a certain historical user has been defrauded within a historical time period. The behavior sequence data can also include social text features and transaction data features. Social text features can represent the text for users to communicate. Transaction data features can refer to the transfer transaction data of a certain historical user within a historical time period. For example, the above execution subject can refer to the training method of the deep neural network model to train the initial false information temporal reasoning model to obtain a trained false information temporal reasoning model. The initial false information temporal reasoning model can be a fusion model of a graph neural network (GNN) and a Transformer.

[0065] In practice, the temporal reasoning model training module can train the initial false information temporal reasoning model through the following steps to obtain a trained false information temporal reasoning model:

[0066] First step, fuse the social text features and transaction data features included in each behavior sequence data in the above behavior sequence dataset to generate fusion features, and obtain a fusion feature set. The behavior sequence data can include multiple behavior data. For example, the social text features and transaction data features included in each behavior data can be dynamically weighted and combined. Among them, the attention mechanism is used to fuse semantic information and behavior features, and its weight assignment is calculated by the following formula:

[0067]

[0068] Among them, represents social text features; represents transaction data features. and are trainable parameters, and the vector after dynamic weighted combination will be used as the input feature of the behavior sequence data.

[0069] : It represents the fusion weight of the social text features and transaction data features in the m-th behavioral data, and is used to measure the attention degree of this behavioral data in the overall behavioral sequence data.

[0070] : It represents the vector representation of the social text features (such as the embedding vectors after the chat records and conversation fragments are encoded by the large language model).

[0071] : It represents the vector representation of the transaction data features (such as the embedding results of structured data such as transfer amount, timestamp, and transaction direction).

[0072] : It represents the fusion input formed by concatenating the two vectors, and is used to capture the cross-modal context.

[0073] : A trainable weight matrix, which acts on the transformation of the concatenated vectors and is used to learn the linear mapping of semantics and structure.

[0074] : A trainable weight vector, which is used to calculate the "similarity" weight in the attention score.

[0075] tanh() : An activation function, which is used to introduce non-linear mapping and improve the model's ability to express complex relationships.

[0076] exp() : It forms a softmax operation with the normalization term in the denominator, so that the sum of the attention weights of all behaviors is 1.

[0077] Step 2: According to the above fusion feature set, train the above initial false information temporal reasoning model to obtain the trained false information temporal reasoning model.

[0078] For example, the Transformer encoder can be used to extract sequence features (referring to the continuous behavioral sequence of users within a certain time window, including events such as login, transfer, registration, device switching, etc. and their timestamps, platforms, device numbers, etc. context features), and its multi-head attention mechanism is calculated as follows:

[0079]

[0080] Among them, Q, K, and V correspond to the query, key, and value matrices respectively, is the dimensionality scaling factor.

[0081] Q: Query Matrix, which is generated from the current input sequence and represents "what content to pay attention to".

[0082] K: Key Matrix, generated from context information, representing "identifiers of content worthy of attention".

[0083] V: Value Matrix, corresponding one-to-one with K, representing the information actually extracted or transmitted.

[0084] : Dimension of the key vector (key dimension scaling factor), used to prevent the gradient from vanishing due to an overly large inner product result, usually the number of columns of K.

[0085] softmax: Normalization function, converting attention scores into a probability distribution such that the sum of all terms is 1.

[0086] Final output: The attention-weighted value matrix V, reflecting the degree of attention of the current input to each item in the entire behavior sequence.

[0087] The behavior sequence data is encoded as a vector sequence and input into the Transformer encoder. The output aggregated representation is h (the global feature vector of the behavior sequence data), and w and b are trainable parameters used for the final risk scoring. The final risk score is output through the Sigmoid function:

[0088]

[0089] h: Global aggregated vector of the behavior sequence (Transformer output), representing the comprehensive representation of the user's behavior within the entire time window.

[0090] Represents the Sigmoid function for risk scoring.

[0091] w: Trainable weight vector for linear mapping.

[0092] b: Trainable bias term, which, together with constitutes the output of the final linear layer.

[0093] Sigmoid activation function: Converts the linear result into a probability value, with an output range of (0, 1), representing the probabilistic meaning of the risk score.

[0094] To ensure the real-time performance of model inference, the system adopts an edge computing and cloud collaboration architecture, and tasks are allocated according to the computational complexity and data volume of the input behavior stream. The specific strategy is as follows:

[0095]

[0096] Among them, is an empirical threshold (such as 1.2 TFLOPS / GB) used to distinguish inference tasks suitable for execution on the edge or in the cloud. This mechanism effectively reduces latency and improves the second-level response ability.

[0097] : The input behavior stream data (behavior sequence data) instance represents a set of user behavior events collected at a certain moment.

[0098] Represents the task allocation policy function.

[0099] FLOPs(x): Behavior stream The required number of floating-point operations for model inference (Floating Point Operations), representing the computational complexity.

[0100] DataSize(x): The volume size of the input data, and the unit can be MB or GB.

[0101] : The empirical threshold (such as 1.2 TFLOPs / GB), representing the ratio boundary between the computational complexity and the data volume. It is the demarcation value for whether the task is suitable for execution on the edge or in the cloud.

[0102] Output: If the ratio is low (i.e., light computation and small data), the inference task is executed on Edge (edge node); if the ratio is high (computation or data is too large), it is transferred to Cloud (cloud center) for execution.

[0103] Step 104, the risk warning module is configured to: identify false information in the above updated dynamic behavior graph according to the above false information time series inference model and the historical abnormal behavior graph library, generate corresponding false identification information, and issue a risk warning.

[0104] In some embodiments, the risk warning module is configured to: identify false information in the above updated dynamic behavior graph according to the above false information time series inference model and the historical abnormal behavior graph library, generate corresponding false identification information, and issue a risk warning. Among them, the above false identification information includes: risk identification results and associated evidence chains.

[0105] In practice, the risk warning module can identify false information in the above updated dynamic behavior graph according to the above false information time series inference model and the historical abnormal behavior graph library through the following steps to generate corresponding false identification information:

[0106] First step, input the above updated dynamic behavior graph into the above false information time series inference model to obtain the behavior risk score corresponding to the above updated dynamic behavior graph as the risk identification result.

[0107] For example, take the output of the trained false information time series inference model as the individual behavior risk score as the basic risk assessment sub-module. Its output and the updated dynamic behavior graph are jointly used as inputs and passed into a fusion module to calculate the group risk score:

[0108]

[0109] Among them, , , are adjustable weights (default values 0.4, 0.4, 0.2), reflecting the importance of entity nodes.

[0110] : Represents the final group risk score, measuring the possibility of organized fraud or abnormal behavior in a whole subgraph (such as a user group).

[0111] : The structural risk score output based on the graph neural network, reflecting the abnormal topological structure (such as the shared relationship of gang-type accounts) among entities in the dynamic behavior graph.

[0112] : The behavior evolution risk score output based on the Transformer model, capturing the fraud behavior chain in the time dimension (such as "induce - add friend - transfer").

[0113] : The graph importance score of the entity node , reflecting its influence or centrality degree in the graph, and the higher it is, the more "critical" it is.

[0114] In the second step, determine the similarity between the above-mentioned updated dynamic behavior graph and each historical abnormal behavior graph in the above-mentioned historical abnormal behavior graph library to obtain a similarity set. The historical abnormal behavior graph library can refer to a database that stores each dynamic behavior graph with abnormal transaction behaviors processed historically. For example, the similarity between the updated dynamic behavior graph G1 and each normal behavior graph G2 in the historical abnormal behavior graph library can be quantified by the following formula:

[0115]

[0116] Among them, is the graph edit distance, is the node overlap penalty factor (default value 0.8).

[0117] : The updated dynamic behavior graph and the historical abnormal behavior graph The similarity score, the closer the value is to 1, the more similar.

[0118] : The updated dynamic behavior graph to be currently recognized, usually the abnormal local area extracted from the real-time graph.

[0119] : The known fraud behavior template graph saved in the historical abnormal behavior graph library.

[0120] The graph edit distance, indicating the minimum number of edit operations (such as adding and deleting nodes, edges, etc.) required to convert to The smaller the value, the more similar.

[0121] : The node overlap penalty coefficient, which controls the normalization range of the similarity. The default value is 0.8. The smaller the value, the greater the difference penalty.

[0122] In the third step, determine the historical abnormal behavior graphs corresponding to the similarities in the above similarity set that meet the preset conditions as the associated historical abnormal behavior graphs, and obtain the associated historical abnormal behavior graph group. For example, the preset condition can be: the similarity is greater than 0.8.

[0123] In the fourth step, in response to determining that the above behavior risk score is greater than or equal to the preset score, perform multi-dimensional verification on the above updated dynamic behavior graph and output multi-dimensional association information. For example, the multi-dimensional verification can include: Device dimension: Check whether the device switching frequency deviates from the normal threshold, that is, the number of times the user changes devices within a certain time window (such as 24 hours). Identify the uniqueness of the device through device fingerprints (such as IMEI, MAC, browser characteristics). If it is found that the same account switches frequently between multiple devices within a short period of time, exceeding the preset threshold (such as 3 times / 24h), it is marked as suspicious and further behavior analysis is triggered. Fund dimension: Analyze whether the transfer amount distribution conforms to the "scattered transfer - concentrated transfer" mode.

[0124] In the fifth step, merge the above associated historical abnormal behavior graph group with the above multi-dimensional association information into an associated evidence chain.

[0125] In the sixth step, merge the above risk identification results with the above associated evidence chain into false identification information.

[0126] For further reference Figure 3 As an implementation of the systems shown in the above figures, some embodiments of the present application provide an intelligent network false information recognition and warning device based on a multi-modal behavior graph. These device embodiments are related to Figure 1Corresponding to the system embodiments shown, the intelligent network false information recognition and early warning device based on the multimodal behavior graph can be specifically applied to various electronic devices.

[0127] As Figure 3 shown, the intelligent network false information recognition and early warning device based on the multimodal behavior graph in some embodiments includes: a collection unit 301, a graph construction unit 302, a model training unit 303, and a risk early warning unit 304. Among them, the collection unit 301 is configured to collect original user behavior data from multiple data sources, where the original user behavior data includes: multiple entity names; the graph construction unit 302 is configured to construct a dynamic behavior graph according to the original user behavior data, and real-time monitor new behavior stream data corresponding to the original user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph; the model training unit 303 is configured to extract positive and negative samples from the historical false case library, construct a behavior sequence data set with time stamps, and train an initial false information time series inference model according to the behavior sequence data set to obtain a trained false information time series inference model, where the false information time series inference model is used to identify the risk score of the dynamic behavior graph; the risk early warning unit 304 is configured to identify false information in the updated dynamic behavior graph according to the false information time series inference model and the historical abnormal behavior graph library to generate corresponding false identification information and perform risk early warning, where the false identification information includes: a risk identification result and an associated evidence chain network.

[0128] It can be understood that the various units described in the intelligent network false information recognition and early warning device based on the multimodal behavior graph correspond to the respective steps in the system described in the reference Figure 1 description. Therefore, the operations, features, and beneficial effects described above for the system also apply to the intelligent network false information recognition and early warning device based on the multimodal behavior graph and the units included therein, and will not be elaborated here.

[0129] Next, refer to Figure 4 , which shows a schematic structural diagram of an electronic device (such as a computing device) suitable for implementing some embodiments of the present application. Figure 4 The electronic device shown is only an example and should not bring any limitations to the functions and usage scopes of the embodiments of the present application. As Figure 4As shown, the computer device includes a processor, a memory, and a network interface connected via a system bus. Among them, the memory may include a non-volatile storage medium and an internal memory. The non-volatile storage medium can store an operating system and computer programs. The computer programs include program instructions that, when executed, can cause the processor to execute any intelligent network false information identification and early warning system based on a multi-modal behavior map. The processor is used to provide computing and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the operation of the computer programs in the non-volatile storage medium. When the computer programs are executed by the processor, the processor can be caused to execute any intelligent network false information identification and early warning system based on a multi-modal behavior map. The network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art can understand that Figure 4 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0130] It should be understood that the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0131] Among them, in one embodiment, the above-mentioned processor is used to run a computer program stored in the memory to implement the following steps: A data acquisition module, configured to: collect raw user behavior data from multiple data sources, where the above-mentioned raw user behavior data includes: multiple entity names; A dynamic behavior graph construction module, configured to: construct a dynamic behavior graph according to the above-mentioned raw user behavior data, and real-time monitor new behavior stream data corresponding to the above-mentioned raw user behavior data, and update the topological structure of the above-mentioned dynamic behavior graph according to the above-mentioned new behavior stream data to obtain an updated dynamic behavior graph; A time-series reasoning model training module, configured to: extract positive and negative samples from a historical false case library, construct a behavior sequence data set with timestamps, and train an initial false information time-series reasoning model according to the above-mentioned behavior sequence data set to obtain a trained false information time-series reasoning model, where the false information time-series reasoning model is used to identify the risk score of the dynamic behavior graph; A risk warning module, configured to: identify false information in the above-mentioned updated dynamic behavior graph according to the above-mentioned false information time-series reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information and perform risk warning, where the above-mentioned false identification information includes: a risk identification result and an associated evidence chain.

[0132] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and the computer program includes program instructions. The system implemented when the program instructions are executed can refer to each embodiment of the intelligent network false information identification and warning system based on a multi-modal behavior graph of the present application.

[0133] Among them, the above-mentioned computer-readable storage medium may be an internal storage unit of the above-mentioned computer device in the foregoing embodiment, such as the hard disk or memory of the above-mentioned computer device. The above-mentioned computer-readable storage medium may also be an external storage device of the above-mentioned computer device, such as a plug-in hard disk equipped on the above-mentioned computer device, a smart media card (SmartMedia Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc.

[0134] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, system, article or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, system, article or system. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, system, article or system including that element.

[0135] The above description is only some preferred embodiments of the present application and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) disclosed in the embodiments of the present application that have similar functions.

Claims

1. An intelligent network false information recognition and early warning system based on a multimodal behavior graph, characterized in that, Including: A data acquisition module, configured to: acquire original user behavior data from multiple data sources, wherein the original user behavior data includes: multiple entity names; A dynamic behavior graph construction module, configured to: construct a dynamic behavior graph according to the original user behavior data, and real-time monitor new behavior stream data corresponding to the original user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph; A time-series reasoning model training module, configured to: extract positive and negative samples from a historical false case library, construct a behavior sequence data set with timestamps, and train an initial false information time-series reasoning model according to the behavior sequence data set to obtain a trained false information time-series reasoning model, wherein the false information time-series reasoning model is used to identify the risk score of the dynamic behavior graph; A risk warning module, configured to: identify false information in the updated dynamic behavior graph according to the false information time-series reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information and perform risk warning, wherein the false identification information includes: a risk identification result and an associated evidence chain; Wherein, constructing a dynamic behavior graph according to the original user behavior data includes: Extracting each entity node and the association relationship between entities from the original user behavior data; Generating a dynamic behavior graph corresponding to each entity node and the association relationship between entities based on a graph database, wherein the node attributes of the entity nodes in the dynamic behavior graph include: timestamp, operation type, edge weight; Wherein, real-time monitoring new behavior stream data corresponding to the original user behavior data and updating the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph includes: Monitoring new behavior stream data corresponding to the original user behavior data in multiple data sources within a preset time period; In response to the new behavior stream data indicating a new device binding an account, parsing the new behavior stream data into a new edge; In response to the new behavior stream data indicating a cross-region login behavior, parsing the new behavior stream data into an updated edge attribute; Updating the dynamic behavior graph according to the new edge and the updated edge attribute; Adjusting the weight of the historical edges of the dynamic behavior graph according to a preset rule; In response to determining that a device corresponding to a device entity node in the dynamic behavior graph meets a preset risk condition, expanding two-hop neighbors outward with the device entity node as the center to construct a subgraph, and recalculating the weights of all edges in the dynamic behavior graph.

2. The intelligent network false information identification and early warning system according to claim 1, characterized in that, Training the initial false information time-series reasoning model according to the behavior sequence data set to obtain a trained false information time-series reasoning model includes: Fusing the social text features and transaction data features included in each behavior sequence data in the behavior sequence data set to generate a fused feature to obtain a fused feature set; Train the initial false information temporal reasoning model according to the fusion feature set to obtain a trained false information temporal reasoning model.

3. The intelligent network false information identification and early warning system according to claim 2, characterized in that The false information identification of the updated dynamic behavior graph to generate corresponding false identification information according to the false information temporal reasoning model and the historical abnormal behavior graph library includes: Input the updated dynamic behavior graph into the false information temporal reasoning model to obtain a behavior risk score corresponding to the updated dynamic behavior graph as a risk identification result; Determine the similarity between the updated dynamic behavior graph and each historical abnormal behavior graph in the historical abnormal behavior graph library to obtain a similarity set; Determine the historical abnormal behavior graph corresponding to the similarity that meets the preset conditions in the similarity set as an associated historical abnormal behavior graph to obtain an associated historical abnormal behavior graph group; In response to determining that the behavior risk score is greater than or equal to the preset score, perform multi-dimensional verification on the updated dynamic behavior graph and output multi-dimensional association information; Combine the associated historical abnormal behavior graph group and the multi-dimensional association information into an associated evidence chain; Combine the risk identification result and the associated evidence chain into false identification information.

Citation Information

Patent Citations

  • Cross-document false information detection method based on contrast graph learning

    CN117852526A

  • Knowledge graph driven power supply chain risk early warning method and related device

    CN119624132A